South Africa has emerged as the leading hotspot for cybercrime across Africa, dominating ransomware, phishing, and business email compromise attacks, according to the latest Interpol assessment. The report highlights the country’s outsized share in various cyber threats recorded across the continent.
Interpol’s African Cyberthreat Assessment Report 2026, which aggregates data from 36 African countries, identifies Southern Africa as both the continent’s most digitally advanced and most targeted region. South Africa alone accounted for the vast majority of ransomware detections in Africa, with cybersecurity firm TrendAI reporting that 92 percent of ransomware incidents originated there. The country also experienced over 200,000 distributed denial-of-service (DDoS) attacks, including one that peaked at 312 gigabits per second.
Phishing attacks were similarly concentrated, with South Africa responsible for roughly 40 percent of all incidents detected by SOCRadar, while 70 percent of business email compromises in 2025 were recorded within its borders. The report signals a troubling trend that cybercrime in Africa has transformed from scattered attacks into an organized, industrial-scale operation enhanced by artificial intelligence tools.
Financial losses due to cybercrime on the continent more than doubled within two years, jumping from $192 million to $484 million since 2024. Criminal enterprises increasingly exploit mobile money platforms, social media, and AI-generated content to defraud victims. The study also reveals that scam centers proliferate, with nearly three-quarters of surveyed countries reporting their presence—particularly in Southern and West Africa.
Interpol’s cybercrime unit director emphasized the accelerating sophistication of attacks driven by AI, which automates key stages from reconnaissance and phishing to extortion and evasion. Despite robust cybersecurity frameworks in Southern Africa, these nations struggle to keep pace with the rapid growth and scale of AI-fueled cyber threats.

